CVE-2007-4419

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
18/08/2007
Last modified:
15/10/2018

Description

Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:olate:olatedownload:3.4.1:*:*:*:*:*:*:*